In February 2022, a new root and intermediate certificate authorities will be used for Azure Storage TLS certificate.
The new authority will be DigiCert Global G2 Root.
For most of Azure Storage deployment this change will have no impact and will be totally transparent.
However if you have explicitly define a list of acceptable CA (also known as certificate pinning) you need to update your deployment to allow the new authority:
DigiCert Global Root G2 using the thumbprint df3c24f9bfd666761b268073fe06d1cc8d4f82a4
Also it is recommended to also add the additional authorities:
DigiCert Global Root G3 using the thumbprint 7e04de896a3e666d00e687d33ffad93be83d349e
Microsoft RSA Root Certificate Authority 2017 using the thumbprint 73a5e64a3bff8316ff0edccc618a906e4eae4d74
Microsoft ECC Root Certificate Authority 2017 using the thumbprint 999a64c37ff47d9fab95f14769891460eec4c3c5